Low latency cloud-assisted network security with local cache
Abstract
Latency in a cloud security service provided via a network security device is reduced by receiving in the network security device a new network connection request for a connection between a local network device and a remote server. If a locally cached rule is applicable to the new network connection request, the applicable locally cached rule is applied to selectively allow the new network connection based on the rule. If no locally cached rule is applicable to the new network connection request, the new network connection request is forwarded to the remote server and to a cloud security service, and a response from the remote server is selectively forwarded to the local network device only upon receiving a determination by the cloud security device as to whether the new network connection is a security risk.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1. A method of reducing latency in a cloud security service, comprising:
receiving, in a network security device, a new network connection request from a local network device to a remote network device;
determining whether at least one locally cached rule applies to the new network connection request;
if a locally cached rule applies to the network connection request, selectively approving the network connection request based on the rule; and
if a locally cached rule does not apply to the network connection request,
forwarding the new network connection request to the remote network device and receiving a response from the remote device in the network security device;
sending data related to the new network connection request from the network security device to a cloud security device and receiving, by the network security device from the cloud security device, data related to the security of the new network connection request; and
selectively forwarding the response received from the remote server from the network security device to the local network device based at least in part on the received data related to the security of the request for the new network connection.
2. The method of reducing latency in a cloud security service of claim 1 , further comprising selectively storing a locally cached rule on the cloud security device based at least in part on the received data related to the security of the new network connection request from the cloud security device.
3. The method of reducing latency in a cloud security service of claim 2 , wherein the received data related to the security of the new network connection request from the cloud security device comprises information related to whether to allow storing a decision regarding allowing the new network connection request as a locally cached rule.
4. The method of reducing latency in a cloud security service of claim 2 , wherein the locally cached rule applies to future events meeting similarity criteria relative to the new network connection request.
5. The method of reducing latency in a cloud security service of claim 4 , wherein similarity criteria comprise at least one of server identity, IP address, root domain, port number, protocol, and packet content.
6. The method of reducing latency in a cloud security service of claim 1 , wherein the local cache comprises rules related to one or more network destinations based on commonly visited across a group of users.
7. The method of reducing latency in a cloud security service of claim 1 , wherein the local cache comprises rules related to one or more network destinations commonly visited on one or more local machines.
8. The method of reducing latency in a cloud security service of claim 1 , further comprising extracting low-level characteristics of the new network connection in the network security device and sending the extracted low-level characteristics as data related to the request for the new network connection to the cloud security service, wherein the low-level characteristics comprise at least one of remote server IP address, port number, protocol, and packet content.
9. The method of reducing latency in a cloud security service of claim 1 , further comprising maintaining a persistent connection between network security device and the cloud security device such that a new connection need not be established for the sending data related to the request for the new network connection from the network security device to the cloud security device.
10. The method of reducing latency in a cloud security service of claim 1 , further comprising searching for a cloud security device having the fastest connection to the network security device, and changing from a current cloud security device to a new cloud security device if the new cloud security device connection is faster than the connection to the current cloud security device by a threshold amount.
11. The method of reducing latency in a cloud security service of claim 1 , wherein the network security device comprises a router, a firewall, or a special-purpose network security device.
12. The method of reducing latency in a cloud security service of claim 1 , wherein selectively forwarding comprises receiving a determination of whether to allow the connection from the cloud security server and selectively forwarding based at least in part on the received determination.
13. The method of reducing latency in a cloud security service of claim 1 , wherein selectively forwarding comprises determining in the network security device whether to allow the connection, based at least in part on the received data related to the security of the request for the new network connection.
14. A network security device, comprising:
a processor, a memory, one or more network connections, and machine-readable instructions executable on the processor when loaded into the memory, the machine-readable instructions operable when executed to cause the network security device to:
receive a request for a new network connection from a local network device to a remote server;
determine whether at least one locally cached rule applies to the new network connection request;
if a locally cached rule applies to the network connection request, selectively approve the network connection request based on the rule; and
if a locally cached rule does not apply to the network connection request:
forward the received request for the new network connection to the remote server;
send data related to the request for the new network connection to the cloud security device and receive a response from the remote server comprising data related to the security of the request for the new network connection from the cloud server; and
selectively forward the response received from the remote server to the local network device based at least in part on the received data related to the security of the request for the new network connection.
15. The network security device of claim 14 , the machine-readable instructions further operable when executed to selectively store a locally cached rule based at least in part on the received data related to the security of the new network connection request from the cloud security device.
16. The network security device of claim 15 , wherein the received data related to the security of the new network connection request from the cloud security device comprises information related to whether to allow storing a decision regarding allowing the new network connection request as a locally cached rule, and wherein the locally cached rule applies to future events meeting similarity criteria relative to the new network connection, the similarity criteria comprising at least one of server identity, IP address, root domain, port number, protocol, and packet content.
17. The network security device of claim 14 , wherein the local cache comprises rules related to one or more network destinations based on at least one of network destinations commonly visited across a group of users and network destinations commonly visited on one or more local machines.
18. The network security device of claim 14 , the machine-readable instructions further operable when executed to extract low-level characteristics of the new network connection in the network security device and send the extracted low-level characteristics as data related to the request for the new network connection to the cloud security service, wherein the low-level characteristics comprise at least one of remote server IP address, port number, protocol, and packet content.
19. The network security device of claim 10 , the machine-readable instructions when executed further operable to maintain a persistent connection between network security device and the cloud security device such that a new connection need not be established for the sending data related to the request for the new network connection from the network security device to the cloud security device.
20. A method of reducing latency in a cloud security service, comprising:
receiving in a network security device a new network connection request for a new network connection between a local network device and a remote serve;
if a locally cached rule is applicable to the new network connection request, applying the applicable locally cached rule to selectively allow the new network connection based on the rule; and
if no locally cached rule is applicable to the new network connection request, forwarding the new network connection request to the remote server and to a cloud security service, and selectively forwarding a response from the remote server to the local network device only upon receiving a determination by the cloud security device as to whether the new network connection is a security risk.Join the waitlist — get patent alerts
Track US11736528B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.